CERT-UA warns of malware campaign conducted by threat actor UAC-0006

2 years ago

The Ukraine CERT-UA warns of a concerning increase in cyberattacks attributed to the financially-motivated threat actor UAC-0006. The Computer Emergency…

<gwmw style="display:none;"></gwmw>Security Affairs newsletter Round 473 by Pierluigi Paganini – INTERNATIONAL EDITION<gwmw style="display:none;"></gwmw>

2 years ago

A new round of the weekly SecurityAffairs newsletter arrived! Every week the best security articles from Security Affairs are free…

Malware-laced JAVS Viewer deploys RustDoor implant in supply chain attack

2 years ago

Malicious actors compromised the JAVS Viewer installer to deliver the RustDoor malware in a supply chain attack. Rapid7 researchers warned…

Fake AV websites used to distribute info-stealer malware

2 years ago

Threat actors used fake AV websites masquerading as legitimate antivirus products from Avast, Bitdefender, and Malwarebytes to distribute malware. In…

MITRE December 2023 attack: Threat actors created rogue VMs to evade detection

2 years ago

The MITRE Corporation revealed that threat actors behind the December 2023 attacks created rogue virtual machines (VMs) within its environment.…

An XSS flaw in GitLab allows attackers to take over accounts<gwmw style="display:none;"></gwmw>

2 years ago

GitLab addressed a high-severity cross-site scripting (XSS) vulnerability that allows unauthenticated attackers to take over user accounts. GitLab fixed a high-severity…

Google fixes eighth actively exploited Chrome zero-day this year, the third in a month

2 years ago

Google rolled out a new emergency security update to fix another actively exploited zero-day vulnerability in the Chrome browser. Google…

CISA adds Apache Flink flaw to its Known Exploited Vulnerabilities catalog

2 years ago

CISA adds Apache Flink improper access control vulnerability to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security…

Usage of TLS in DDNS Services leads to Information Disclosure in Multiple Vendors

2 years ago

The use of Dynamic DNS (DDNS) services embedded in appliances can potentially expose data and devices to attacks. The use…

Recall feature in Microsoft Copilot+ PCs raises privacy and security concerns

2 years ago

UK data watchdog is investigating Microsoft regarding the new Recall feature in Copilot+ PCs that captures screenshots of the user's…

This website uses cookies.